Exeon Analytics

Swiss AI-powered network detection and response platform built on metadata, not full packet capture

Quick Overview

Company Exeon Analytics AG
Category SIEM & Security Monitoring
Headquarters Zurich, Switzerland
EU Presence Switzerland (adequacy decision, outside the EEA)
Open Source No
Pricing Custom quote scoped to network size; no published price list, demo on request
Free Option Demo on request
Replaces Darktrace, Vectra AI, ExtraHop

Detailed Review

Exeon Analytics is a Zurich-based network detection and response platform that builds behavioural baselines from network metadata rather than full packet capture, which keeps sensitive payload contents out of the analysis pipeline while still surfacing lateral movement, command-and-control traffic and ransomware behaviour across on-premises, private-cloud and public-cloud environments.

The company began as a spin-off from ETH Zurich, and the platform layers user and entity behaviour analytics on top of the same metadata stream rather than requiring a second, separate data collection effort to run alongside it.

Where the SIEM and EDR products in this category detect from logs and endpoint agents, Exeon detects from the network itself, which matters when a compromised system cannot be trusted to report on itself or cannot run an agent at all — OT equipment and unmanaged devices are the obvious cases.

That makes it a complement to a SIEM rather than a replacement for one, and it is priced and sold accordingly, on a per-deployment quote rather than a published tier.

Exeon does not publish pricing; every engagement starts with a demo and a quote scoped to network size, rather than a plan comparison, which suits an enterprise sales motion more than a self-serve one. Hosting and processing stay in Switzerland, which sits outside the EU but is treated as data-protection adequate — worth noting for organisations to whom EU membership itself, not just adequacy, is the actual requirement.

What Exeon Analytics does well

  • Metadata-based NDR, no packet payload capture
  • UEBA layered on the same data stream
  • Deployable on-prem, private or public cloud
  • ETH Zurich engineering pedigree
  • Sees traffic agents and logs miss (OT, unmanaged devices)

Where Exeon Analytics falls short

  • No published pricing — quote only
  • Complements a SIEM rather than replacing one
  • Newer and smaller than Darktrace or Vectra AI
  • Switzerland is adequacy-based, not EU membership

Standout feature. Detects from network metadata alone, so devices too old or too locked-down to run an agent are still covered.

Pros and Cons

Pros

  • Metadata-based NDR, no packet payload capture
  • UEBA layered on the same data stream
  • Deployable on-prem, private or public cloud
  • ETH Zurich engineering pedigree
  • Sees traffic agents and logs miss (OT, unmanaged devices)

Cons

  • No published pricing — quote only
  • Complements a SIEM rather than replacing one
  • Newer and smaller than Darktrace or Vectra AI
  • Switzerland is adequacy-based, not EU membership

Alternatives to Exeon Analytics

See all SIEM & security monitoring →

Frequently Asked Questions

What is Exeon Analytics?

Exeon Analytics is a Zurich-based network detection and response platform that builds behavioural baselines from network metadata rather than full packet capture, which keeps sensitive payload contents out of the analysis pipeline while still surfacing lateral movement, command-and-control traffic and ransomware behaviour across on-premises, private-cloud and public-cloud environments.

The company began as a spin-off from ETH Zurich, and the platform layers user and entity behaviour analytics on top of the same metadata stream rather than requiring a second, separate data collection effort to run alongside it.

Where is Exeon Analytics based?

Exeon Analytics operates from Zurich, Switzerland, which places it under Switzerland (adequacy decision, outside the EEA).

What does Exeon Analytics cost?

Custom quote scoped to network size; no published price list, demo on request. Demo on request.

Who is Exeon Analytics best for?

Network-level detection where agents cannot run. Detects from network metadata alone, so devices too old or too locked-down to run an agent are still covered.

What are the drawbacks of Exeon Analytics?

No published pricing — quote only. Complements a SIEM rather than replacing one. Newer and smaller than Darktrace or Vectra AI. Switzerland is adequacy-based, not EU membership.

Is Exeon Analytics a good alternative to Darktrace?

Exeon Analytics is built as a European alternative to Darktrace: Swiss AI-powered network detection and response platform built on metadata, not full packet capture. It will not be a like-for-like feature match in every respect, so check the review above for where the two genuinely differ before switching.

How does Exeon Analytics compare to other SIEM & Security Monitoring tools?

Exeon Analytics is one of several European SIEM & Security Monitoring tools we cover. It is most often compared with Darktrace, Vectra AI, ExtraHop.

About the author

One person researches and writes every tool page on European Purpose and checks the compliance and pricing claims against the vendor's own documentation.

Sebastiaan Smits

Sebastiaan Smits

Founder · Amsterdam, Netherlands

Founder of European Purpose. Researches and writes the reviews and checks where each company is actually established.

Read our editorial process for how we source, verify and update these pages, and how paid placement works.

Go to Exeon Analytics